VulnerabilityModified
CVE-2007-0144
Cross-site scripting (XSS) vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the ordernum parameter.
MEDIUM 6.8EPSS 1.87%
Does this matter?
Lower severity and a low EPSS score (1.87%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the ordernum parameter.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.87% probability · 78th percentile
- CISA KEV
- Not listed
- Affected
- digitizing quote and ordering system/digitizing quote and ordering system
- Source
- cve@mitre.org
References
- http://osvdb.org/31690
- http://secunia.com/advisories/23652Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31321
- https://www.exploit-db.com/exploits/3089
- http://osvdb.org/31690
- http://secunia.com/advisories/23652Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31321
- https://www.exploit-db.com/exploits/3089
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.